AI governance program

Can you show that your people know how to use AI?

Not that you sent a policy round. That this person, in this role, on this date, demonstrated they can recognise a wrong answer, refuse it, and say why. That is the record you are being asked for, and a slide deck does not produce it.

Where the rules actually stand today.

The picture changed in June 2026 and a lot of published advice is now out of date. Here is the current position, verified 25 July 2026.

The AI literacy duty is live now
Article 4 has applied since 2 February 2025. Supervision and enforcement start 2 August 2026. It was softened, not removed, and it now reads as a duty to support and promote AI literacy with proportionate measures.

Softer wording, heavier evidence
A duty of effort has no threshold to point at, so you discharge it by showing what you actually did. Documented, dated, differentiated by role. The record is the compliance position.

High risk moved to December 2027
The Digital Omnibus deferred stand alone high risk obligations from August 2026 to 2 December 2027. That is planning time, not a reprieve, because the oversight preconditions take longer to build than the training takes to deliver.

Three things force this, and none of them is a fine.

Your customer asks before they buy

AI governance questions are now standard in enterprise procurement, and an unanswered questionnaire loses the deal long before a regulator would ever look at you. Revenue protection moves budget faster than risk ever has.

Your works council can stop the rollout

In Germany and much of DACH, co determination covers practically any AI that touches people. Without an agreement the rollout is legally ineffective, and a training and oversight concept is a standard clause. That is a blocker in your own building, not a regulator in two years.

Your auditor asks for names and dates

Certification and surveillance audits want the competence record, not the curriculum. Attendance lists do not answer the question, and reconstructing evidence afterwards is exactly what auditors are trained to spot.

What you install.

A complete program, not a course library. Each piece declares the article it rests on and the date that reading was verified.

Policies your organisation adopts

An AI use policy and a human oversight standard, written as documents a company would put its name on. They go through your approval and signature flow and become controlled documents.

Six role based paths

From awareness for everyone through to the people who hold oversight. Depth follows the role, the risk and the context, which is what the law asks for and what a single company wide course cannot deliver.

Scenario based competence evidence

Realistic situations with hidden risks and time pressure, graded against criteria rather than a pass mark. A multiple choice score proves recall. It does not prove someone will refuse a confident wrong answer.

Assignment rules that find the right people

Targeting by department, activity, plant, line and workstation, so the oversight path reaches the people who actually hold the authority to stop something. One rule carries both the course somebody takes and the policies they must read, and you confirm the mapping before anything is assigned.

Six levels, because one course for everyone is the finding.

Requirements follow the role, the decisions it carries, and who is affected. Each person sits at one level, and the level says what they must be able to do, not how many slides they saw.

A

Awareness

Recognises where AI is in use, knows the rules and where to get help.

B

Responsible user

Uses approved tools, checks results against a real source, escalates uncertainty.

C

Professional operator

Runs defined checks, decides whether output is usable, handles exceptions.

D

Human oversight

Detects anomalies and automation bias, rejects output, stops the process, documents the intervention.

E

Specialist

Assesses models, data and controls, analyses failures, supports risk work and incidents.

F

Governance and leadership

Sets risk appetite, provides resources, takes release and escalation decisions.

What the evidence looks like when someone asks.

This is the part that is hard to build and easy to demand. Better Comply produces it as the work happens, so nothing has to be assembled the night before.

  • Per person, per role, per content version, with electronic signature and server side timestamp
  • The exact document version each person was trained on, kept immutable once evidence references it
  • Coverage by role and by department, including who is missing and who is overdue
  • A full audit trail of every approval, including who approved what and who was not allowed to

What this does not do.

It is not legal advice, and classifying a specific system as high risk needs current legal review of your actual use case. The scenario assessments are graded by a reviewer in your organisation rather than automatically, because a machine deciding whether a person is competent to supervise a machine is a line worth not crossing. Where a path is recall only, the program says so instead of calling it competence.

Bring one AI use case. We will show you the evidence chain.

A focused walkthrough on a system you actually run, with the roles you actually have, ending at the record you would hand an auditor.

Request a walkthrough